• Routing between existing LAN's

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ
    You would port forward ports 502-508 from lan 2 pfsense IP to 192.168.0.4, and also setup source natting (outbound nat) So that 192.168.0.4 thinks its coming from the pfsense 192.168.0.X IP. Now when 192.168.2.10 tries to talk to pfsense 192.168.2.x IP it would be sent to 192.168.0.4
  • Multi-Wan as a backup connection not failover/load balancing

    2
    0 Votes
    2 Posts
    327 Views
    V
    @dan2112 The LTE connection can only be used for outbound traffic if there is any route defined to go over it. So if there is no route, no traffic. If you only want to use it for a dial-in VPN, you don't need to set it as gateway. Simply connect the LTE modem to a pfSense interface and fire up an OpenVPN server listening on this interface. You will also need a dynamic DNS for the LTE, so you can connect to the hostname when you need.
  • Packet loss with multiple VPN clients

    7
    0 Votes
    7 Posts
    975 Views
    DaddyGoD
    @townsenk64 said in Packet loss with multiple VPN clients: monitor gateway such as 8.8.8.8 or 1.1.1.1. These give exactly the results that the DNS server load gives, not so relevant, DNS servers are not designed to respond to ICMP, but I know this is often the only solution. (this is not the main objective with them = ICMP respons) f.e.: Neither SurfShark nor ExpressVPN gateway not respond to ICMP. (security question) Tracert...... and it will tell you what is the nearest upstream GW in your VPN tunnel that responds to ICMP I wouldn't think it's a "dpinger" issue, because it works for me and others. What I would do next: First check the parameters of the WAN-only with ISP connection (pls. heavy load the link, for example with this: https://speed.cloudflare.com/ or https://www.nperf.com/en/) I would take down all the VPN tunnels and bring them up one by one In the meantime, I would monitor the hardware CPU load, as OpenVPN is a single-threaded beast Step by step I would launch VPN tunnels, after you should see if doing so increases packet loss and CPU load BTW: What type of ISP connection do you have? (PPPOE, GPON, ADSL, etc)
  • USB Modem is always down

    5
    1
    0 Votes
    5 Posts
    755 Views
    A
    Further investigation I issued the statement via shell usbconfig It then displayed: ugen0.1: <Marvell XHCI root HUB> at usbus0, cfg=0 md=HOST spd=SUPER (5.0Gbps) pwr=SAVE (0mA) ugen1.1: <Marvell EHCI root HUB> at usbus1, cfg=0 md=HOST spd=HIGH (480Mbps) pwr=SAVE (0mA) ugen0.2: <HUAWEI Technology HUAWEI Mobile> at usbus0, cfg=0 md=HOST spd=HIGH (480Mbps) pwr=ON (500mA) I then checked those devices: ls -l /dev/ugen* It then displayed: lrwxr-xr-x 1 root wheel 9 Jun 4 21:44 /dev/ugen0.1 -> usb/0.1.0 lrwxr-xr-x 1 root wheel 9 Jun 4 21:43 /dev/ugen0.2 -> usb/0.2.0 lrwxr-xr-x 1 root wheel 9 Jun 4 21:44 /dev/ugen1.1 -> usb/1.1.0 The USB device is on /dev/ugen0.2 but the Netgate device's PPP is only acknowledging /dev/cuau0 I also tried editing the file /etc/ppp/ppp.conf and tried to replace anything the says "cuau*" into "ugen*" to test if it is about the configurations. I rebooted the device and after it was on, Netgate still just recognizes /dev/cuau0 on the PPP lists and not /dev/ugen0.2 Do you guys know what could be done to solve this? Any hint or direction is much appreciated
  • Routing between WAN and LAN

    34
    0 Votes
    34 Posts
    11k Views
    johnpozJ
    @brandon-lizard said in Routing between WAN and LAN: Why does this have to be so hard? Its not hard... You have been given multiple options..
  • MultiWan Load Ballancing faild

    3
    0 Votes
    3 Posts
    487 Views
    V
    @townsenk64 Yes sometime i get packet loss, but most of the time its stable and loss is 0%.. [image: 1622698022589-3ac3902b-e7dc-45a4-a2d3-676f79e77016-image.png]
  • 0 Votes
    5 Posts
    1k Views
    N
    @townsenk64 Thankyou really appreciate all the insight
  • [Solved] Spectrum Static over DHCP

    2
    0 Votes
    2 Posts
    196 Views
    L
    I had realized I had forgotten to add my NAT rule into my list as I am manually natting on pfSense. Once I added the VIP's and NAT rule, I was able to ping externally. Sometimes it pays to step away and look at it again a different day.
  • create various default gateway pfsense

    1
    0 Votes
    1 Posts
    134 Views
    No one has replied
  • Static Route VS Outbound

    21
    1
    0 Votes
    21 Posts
    2k Views
    B
    @johnpoz Thanks for explaining everything. I tried what you suggested and is succesful. The only thing was that the remote user, couldn't been able to connect through a VPN Client, that's why i make it short term access using port 100. ok, now it's clear.
  • routing between two internal networks

    11
    1
    0 Votes
    11 Posts
    1k Views
    B
    @KOM the original diagram had a second pfSense box in the 10.x network but was followed with a question mark to show it was possible. i admit not clear. thanks for the suggestions, it makes sense and i will give it a shot! @johnpoz if you cannot follow this topology of a simple network, there is little else i can provide to help you. and your insistence that your earlier rant about 10.x subnets was simply to find out my level of networking experience is ludicrous and a very transparent attempt at covering up your inability to simply admit that that line of snarkiness had nothing to do with the question at hand. have a great memorial day weekend. technical skills are a dime a dozen, technical skills coupled with empathy and understanding are invaluable.
  • multi-wan load balancing with more than 2 WAN, High Availability.

    2
    0 Votes
    2 Posts
    373 Views
    DaddyGoD
    @vinicius-santosl said in multi-wan load balancing with more than 2 WAN, High Availability.: If possible, how can it be done? Hi, You can run it smoothly , the descriptions are only examples. Pick up the gateways and configure them here (GW Group) following the Netgate guide and this should also help, I repeat myself here: https://forum.netgate.com/topic/163934/sg-3100-loadbalance-and-failover/4?_=1622307884780 This will help (this is a rough link - suddenly- I couldn't find a better one for you): https://www.cyberciti.biz/faq/howto-configure-dual-wan-load-balance-failover-pfsense-router/?cf_chl_captcha_tk=b19a8d5b347fd3f6a25579b8c123f3ca7dd76d3a-1621868538-0-AaaAJyc-XA0E_URuyvq0PWv1HMcVWaLA4YlA9uq7f61D_EDbT6SdOjLrN1YNALceSrBn9ni3SZ0nlGyt5I_Tq84TJGAbMGvFE9M7ZUbtNDxplLM-ZDHu6NnftrAaEQiFjYg0SgL9q-83tjIlR1-hq6N5VWtGAqZW-u-sKKAHkSDa1EG4FRJdiQHDSekvGkAr93cuC4GnTw2McCMXeac3PZGteBkSCKnT5IkEPmR1oP7rJur3TAmtorH07uMw3O73r53cFKo29BCVD04qJ07Qqe86tKSZw2SQEskOz20mes1NUh1CMK1LPO7vJaSfqjgEl6pVzIX_tK-0-pzww_zsjSaX0iNlwF5JfEMBwmvxlgRnodHOCufP-w35cf8KbvnRKQGLaKS__z1tTiZiS5WiDldda7TcLE8xLL10jbHjV0eMrUrmmbxYSl_KiInn8845gbYf4I2yNrt2T6GMCAXXtQpWD6v3kQcl4VMKwCD_LL_BP9uy0ufhoBoFhjS-j1cbThASyTs8WufVhg143Rj2seGN4SKQsXmwHdUNzzJ_DOv7TucHqZhY0ZmiCG2QNqRLPRZ2rsl5wJi1oXadTQTrTpLVvfWVXdePbuzjslThiK10ztKkbfr6JqOAxQ2xWXnRG7fRqKFXE5Z5p_bVWVh8yoKa78YY2ag107cLwOp3J2lJtNiWSiIGC-mcRFx7FyMPqSitREY1-u-1gJh95ulIogyvrYz_LNtVDcyJ-WEgVhKah2KFo6Kg6cuFzHDiFEMf4w [image: 1622308052523-59fea0be-99d4-4079-96a0-adcf3e41a515-image.png]
  • route one site via openvpn

    12
    2
    0 Votes
    12 Posts
    1k Views
    L
    @kom I agree with you but for some reason it was failing to ping the gateway. thanks for your help along the way
  • Dual WAN with Spectrum / Google Fiber - Route Roku TV app

    2
    0 Votes
    2 Posts
    590 Views
    KOMK
    @smithgcovert You could run a packet capture filtered on your TV device to see what it's talking to and on which ports when you run your Spectrum app. From there you would create rules to direct traffic from that device to those IPs/ports out the WAN2 gateway. The trick is separating traffic the device normally generates versus the traffic specifically from the Spectrum app so you might have to play around with it.
  • 0 Votes
    12 Posts
    1k Views
    ymcanY
    @viragomann Thank you so much for taking the time to answer my queries, and to educate me, I really appreciate that. I'm learning new things all the time.
  • Forward google.com to google.de or any other domain??

    1
    0 Votes
    1 Posts
    148 Views
    No one has replied
  • Routing only pfsense configuration

    7
    0 Votes
    7 Posts
    5k Views
    M
    @mountainlion I disabled pf filter, now I cant get admin gui access. From console, I was able to issue pfctl -e and the gui still didnt work. I shutdown and started, still no go. Any ideas how to re-enable the gui after issuing the "disable pf-filter"?
  • Multi-wan Azure Dyndns updates not working when primary WAN is unplugged

    2
    0 Votes
    2 Posts
    370 Views
    N
    I seem to have resolved this issue by reinstalling an older version of pfSense v2.4.5. With that in mind, I believe this to be a bug with v2.5.1.
  • 0 Votes
    16 Posts
    2k Views
    johnpozJ
    @marekandreansky said in Adding secondary WAN to existing network without completely changing topology: Does seem a shame that they only have dual cores and 2GB of ram. Why - do you need a Ferrari to drive to the corner store, or will that Sonata work? Do you really need more horse power than needed to pull the plow, or do you need 8 Clydesdales? This is an appliance this going to really do 1 thing.. Well actually a few things, but It will do it well, it will do it for a long time, and it will use very little power doing it. The appliance update whenever a new version comes out - with appliance you get pfsense+ just use to be call FE vs CE..
  • route traffic from local host though site-to-site VPN

    4
    0 Votes
    4 Posts
    668 Views
    V
    @spacebass You have to route SMTP traffic from public sources over from B to A. To send response packets back the correct path to B instead out to the default gateway, there is a special traffic marking required, called reply-to. But as far as I know, this doesn’t work on IPSec interfaces and it doesn‘t work on CE 2.5.1.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.